CVE-2018-8836

MEDIUM

WAGO 750 Series PLCs < 10 - Denial of Service via TCP Handshake Exploitation

Title source: llm
STIX 2.1

Description

Wago 750 Series PLCs with firmware version 10 and prior include a remote attack may take advantage of an improper implementation of the 3 way handshake during a TCP connection affecting the communications with commission and service tools. Specially crafted packets may also be sent to Port 2455/TCP/IP, used in Codesys management software, which may result in a denial-of-service condition of communications with commissioning and service tools.

Scores

CVSS v3 5.3
EPSS 0.0363
EPSS Percentile 88.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-404
Status published
Products (8)
wago/750-829_firmware < 10
wago/750-831_firmware < 10
wago/750-852_firmware < 10
wago/750-880_firmware < 10
wago/750-881_firmware < 10
wago/750-882_firmware < 10
wago/750-885_firmware < 10
wago/750-889_firmware < 10
Published Apr 03, 2018
Tracked Since Feb 18, 2026